🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a2d5eeff523fcc9916e6ac3cae975b29b36caae284e14f5f0b317ce186192a4d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a2d5eeff523fcc9916e6ac3cae975b29b36caae284e14f5f0b317ce186192a4d
SHA3-384 hash: be7ead130f0f5359aefcb327a6e97e794a5cf107763c8d01c023407ac0f4fc19a16dca9c0ada415bbe865b77c748bc40
SHA1 hash: 2ffb9bcc8f4849664cedcb97c92f82866be43722
MD5 hash: e034b6a8d95bc1c6e5f4e0ce4491d7a9
humanhash: hot-comet-twelve-hotel
File name:comitato_113.zip
Download: download sample
Signature Gozi
File size:1'996 bytes
First seen:2022-03-18 08:47:27 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 48:9soYV4wzSRbCFbTrjt9Y5Uza11YqGRrc+U9ip7qSh5IIdK+Mq:yDmRbCBrjt9Y51qYolq2Vv
TLSH T154410CAA7F3E9C53C0CE4A3AD255CA5085658C1327E12B4F1C644DC6CAC5A1F5795819
Reporter JAMESWT_WT
Tags:agenziaentrate Gozi isfb Ursnif zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
417
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
cmd evasive mshta powershell
Result
Malware family:
n/a
Score:
  10/10
Tags:
n/a
Behaviour
Modifies Internet Explorer settings
Modifies data under HKEY_USERS
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Blocklisted process makes network request
Malware Config
Dropper Extraction:
http://onlinerlines.top/index.php
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments